← Back to Blog

The Scams Actually Hitting Indian Businesses Right Now

A Pune shopkeeper lost money to a swapped QR code. A Mumbai businessman lost 58 crore to a fake CBI call. Here is what is actually hitting Indian SMEs right now, with real cases and sources.

In January 2026, a sweet shop owner in Pune noticed something odd. Customers kept insisting they'd paid, and he had no record of receiving anything. It took him three days to figure out that someone had pasted a fake QR code sticker over his own, quietly rerouting every payment to a stranger's account. By the time he filed a complaint, he'd lost around ₹14,000, not a huge sum on its own, but enough to make him check every QR code in his shop every single morning since.

A few hundred kilometres away in Khajuraho, the same trick hit ten to twelve shopkeepers at once. Police eventually traced it to three men from Jhansi who'd been swapping stickers overnight and living off the redirected payments. One was arrested when a medical store owner got suspicious and pulled his CCTV footage.

These aren't isolated stories. We run fraud detection for Indian SMEs and CA firms at ScamShield AI, and over the past several months we've watched a handful of scam patterns show up again and again, on WhatsApp, in email, in messages people forward asking "is this real?" What follows isn't a generic list of tips. It's what we've actually seen, backed by cases and official warnings you can go verify yourself.


The fake GST notice problem got bad enough that CBIC had to say something

In January 2026, the Central Board of Indirect Taxes and Customs publicly responded to a taxpayer complaint on X about receiving a call from a fake GST officer. CBIC confirmed what businesses had been suspecting: fraudsters were sending summons that copied the CGST logo and stamped them with fabricated Document Identification Numbers to look genuine. By March, the Bengaluru zone office had gone further, issuing Trade Notice No. 02/2026, spelling out plainly that CGST officers never ask for payment through personal UPI IDs or wallets, and never request sensitive information over WhatsApp or SMS.

If you run a business and something claiming to be a GST notice lands in your inbox or your phone, there's a real tool for checking it before you respond to anything. CBIC's DIN verification page will tell you in seconds whether the number on the notice actually exists in their system. If it doesn't come back verified, it isn't real, no matter how convincing the letterhead looks.


UPI collect requests and QR codes, the part almost nobody explains clearly

Here's the one rule that would have stopped both the Pune and Khajuraho cases, and honestly most UPI fraud aimed at businesses: your UPI PIN is only ever needed to send money. Never to receive it. If a "collect request" or a QR scan is asking you to enter your PIN before money supposedly lands in your account, that's the transaction moving in the wrong direction, and it's moving out of your account, not in.

This sounds obvious written down, but in the middle of a busy shop counter or a rushed WhatsApp exchange with someone posing as a delivery partner or supplier, it's exactly the moment people stop reading carefully. Worth building a habit of glancing at the merchant name your app shows after any scan, especially if you haven't checked that particular QR code in a while.


Digital arrest calls have moved from targeting retirees to targeting business owners with real money

This is the one that worries us most, because the sums involved keep climbing. In 2025, a 72 year old businessman in Mumbai was contacted by fraudsters posing as Enforcement Directorate and CBI officials, told his name had surfaced in a money laundering case, and kept under video surveillance for weeks. He transferred ₹58 crore across multiple RTGS payments before realising what had happened. It's still one of the largest single losses reported in this kind of scam anywhere in India.

Earlier this year, a Delhi businessman lost ₹48.56 lakh over four days after being told to stay visible on a video call at all times or face "immediate legal consequences." The CBI chargesheet on that case describes a genuinely structured operation, mule accounts, layered transfers, the works.

No Indian investigating agency conducts an arrest, digital or otherwise, over a video call, and none of them will ever ask you to transfer money to "prove your innocence" or resolve an investigation. If a call like this happens, the right move is to hang up and independently look up the agency's actual number rather than call anything given to you during the conversation.


The electricity disconnection message that isn't from your DISCOM

This one runs on a script that's barely changed in years, but it keeps working because it hits businesses where a power cut genuinely hurts: lost hours, spoiled stock, unhappy customers. A message arrives, often badly worded, claiming your connection will be cut that same evening over an unpaid bill, with a number to call immediately. Call it, and you're usually handed off from a fake "lineman" to a fake "junior engineer" who asks you to pay a small verification fee or install a screen sharing app to "fix the account."

The scale of this one is bigger than most people realise. India's Department of Telecom used its Chakshu fraud reporting portal to trace this exact pattern and ended up ordering telecom providers to block 392 mobile handsets and re-verify more than 31,000 connections tied to electricity impersonation scams. That's not a handful of opportunists. That's an operation.

Real electricity providers bill through their own app or website, and disconnection requires weeks of written notice, not a same day WhatsApp threat. If you get one of these, check your actual account through the DISCOM's app before doing anything else.


What ties all four of these together

Every one of these cases starts the same way. Something arrives that looks like it's from an authority you'd never ignore, your tax department, your bank, the police, your power company, paired with a deadline that doesn't leave room to think it through, and a channel (a link, a number, a QR code) that pulls you off the real, verifiable path and onto one the scammer controls.

Once that pattern is visible, it holds up against scams that haven't been invented yet too. But recognising the pattern in the moment, on a phone, mid workday, with a deadline attached, is genuinely hard. That's the actual problem, not a lack of awareness, but the fact that a small team getting dozens of messages a day can't slow down and fact check every single one.

That's the gap we built ScamShield AI to close, automated scanning across WhatsApp, email, and screenshots, tuned specifically for how Indian businesses and CA firms actually communicate day to day. If you want to see what it flags on messages you're actually receiving, it's live at scamshieldai.in.

If you've run into a version of one of these that didn't quite match what's described here, we'd genuinely like to hear about it. New variants show up every few weeks, and the ones we haven't documented yet are usually the ones worth knowing about first.